๐Ÿ” CVE Alert

CVE-2026-98374

UNKNOWN 0.0

tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() When tcp_send_synack() replaces the cloned SYN skb at the head of the retransmit queue with a copy, it frees the original with tcp_rtx_queue_unlink_and_free() and only repairs tp->highest_sack. tp->retransmit_skb_hint keeps pointing at the freed skbuff_fclone_cache object. The dangling hint is read in tcp_verify_retransmit_hint() and used as the root of the rbtree walk in tcp_xmit_retransmit_queue(). An unprivileged TFO client (sendmsg(MSG_FASTOPEN)) can arm the hint with an attacker-supplied ICMP fragmentation-needed message, after which a simultaneous open frees the armed SYN skb: BUG: KASAN: slab-use-after-free in tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316) Read of size 4 at addr ffff88800604d928 by task swapper/1/0 Call Trace: tcp_mark_skb_lost (net/ipv4/tcp_input.c:1316) tcp_simple_retransmit (net/ipv4/tcp_input.c:3158) tcp_v4_err (net/ipv4/tcp_ipv4.c:587) Sync the hint to the copy.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
c31b70c9968fe9c4194d1b5d06d07596a3b680de < fad6d429651e748365e93ca54645accc212f0018 c31b70c9968fe9c4194d1b5d06d07596a3b680de < c5b4da1f403a658c1c19766be2b426003ada419f c31b70c9968fe9c4194d1b5d06d07596a3b680de < 71d45049b0d631dfdbf3c65305f7fca676de023b c31b70c9968fe9c4194d1b5d06d07596a3b680de < e3ea71cb1408a013ed4e8a757b815f1a919324bd c31b70c9968fe9c4194d1b5d06d07596a3b680de < 631aa4cb45099f09e9385dd786bd291c6270bfc4 c31b70c9968fe9c4194d1b5d06d07596a3b680de < 0f87720c7e4bcab07c24888b3cf12bfe857bb90e c31b70c9968fe9c4194d1b5d06d07596a3b680de < fe99bbeee5c5dbd3abc30721a8079ced59649d97
Linux / Linux
5.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/fad6d429651e748365e93ca54645accc212f0018 git.kernel.org: https://git.kernel.org/stable/c/c5b4da1f403a658c1c19766be2b426003ada419f git.kernel.org: https://git.kernel.org/stable/c/71d45049b0d631dfdbf3c65305f7fca676de023b git.kernel.org: https://git.kernel.org/stable/c/e3ea71cb1408a013ed4e8a757b815f1a919324bd git.kernel.org: https://git.kernel.org/stable/c/631aa4cb45099f09e9385dd786bd291c6270bfc4 git.kernel.org: https://git.kernel.org/stable/c/0f87720c7e4bcab07c24888b3cf12bfe857bb90e git.kernel.org: https://git.kernel.org/stable/c/fe99bbeee5c5dbd3abc30721a8079ced59649d97